mirror of
https://github.com/curl/curl.git
synced 2026-08-01 17:50:28 +03:00
Fixed CA cert verification using GnuTLS with the default bundle, which
previously failed due to GnuTLS not allowing x509 v1 CA certs by default.
This commit is contained in:
parent
a142372750
commit
432dfe2b8f
3 changed files with 12 additions and 2 deletions
|
|
@ -151,13 +151,18 @@ Curl_gtls_connect(struct connectdata *conn,
|
|||
|
||||
if(data->set.ssl.CAfile) {
|
||||
/* set the trusted CA cert bundle file */
|
||||
gnutls_certificate_set_verify_flags(conn->ssl[sockindex].cred,
|
||||
GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT);
|
||||
|
||||
rc = gnutls_certificate_set_x509_trust_file(conn->ssl[sockindex].cred,
|
||||
data->set.ssl.CAfile,
|
||||
GNUTLS_X509_FMT_PEM);
|
||||
if(rc < 0) {
|
||||
if(rc < 0)
|
||||
infof(data, "error reading ca cert file %s (%s)\n",
|
||||
data->set.ssl.CAfile, gnutls_strerror(rc));
|
||||
}
|
||||
else
|
||||
infof(data, "found %d certificates in %s\n",
|
||||
rc, data->set.ssl.CAfile);
|
||||
}
|
||||
|
||||
/* Initialize TLS session as a client */
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue